Quantcast
Channel: All Centrify Express posts
Viewing all 1833 articles
Browse latest View live

Re: Where to download Centrify Express for MAC Agent


Re: Where to download Centrify Express for MAC Agent

$
0
0

Hi ,

 

We are really sorry about this. Our web team has fixed the bad link on the Mac Express download page. Please let me know if you run into any additional issues.

 

Regards,

Unable to authenticate to websites using Chrome 63.0.3239.132 on OSX 10.13.2

$
0
0

I'm trying to get myself set up to be able to authenticate to websites in Chrome using my CAC on my Macbook. I have a smart card reader; Smart Card Assistant (Centrify Express for Smart Card) installed and recognizing my card; all necessary certificates installed and recognized. I am able to authenticate to, for instance, myaccess.dmdc.osd.mil using Safari. It prompts for my PIN. After I enter it I am sent to the page I'm accessing.

 

When attempt to log into the above website using Chrome, I instead get "ERR_BAD_SSL_CLIENT_AUTH_CERT". It doesn't prompt for my PIN. The certificates are never presented for selection and aren't being sent to the site. I've tried the option in Chrome to manage certficates but this simply opens Keychain Access. My CAC is listed with its certificates. I'm not able to link these certificates to Chrome in any way. I've even tried to add a New Identity Preference but the only certificates given to select are from Apple.

 

What special steps do I need to take to get this to work with Chrome?

Android app does not complete multi-factor authentication

$
0
0

Good afternoon all,

 

I have a co-worker using a Samsung Galaxy Note 4 running Android 6.0.1 attempting to login with Microsoft Staff Hub app, but it never completes the multi-factor authentication.  It shows attempting to call *** *** ####, but no call is received.

 

Any suggestions?

Re: Unable to authenticate to websites using Chrome 63.0.3239.132 on OSX 10.13.2

Re: Android app does not complete multi-factor authentication

$
0
0

Hi skeown,

 

Welcome to Centrify Community!

 

May I know which country code and the phone format you entered for this user? The call will be failed if this is an incorrect phone number or in an inappropriate format. Please make sure the phone number of the user is correct. Besides, stating the country code will make things clear. Here is the example, if the mobile phone is in Japan, the mobile number should be in this format: +81 11112222 

 

If it is still failed, please add 'email confirmation code' or other challenges in Authentication Profiles to unblock user enrollment. 

 

Hope this will help. Please let us know if you have further questions. Thank you.

 

Kind Regards,

Yeny

 

Can I add a network share into my Centrfy Company Apps?

$
0
0

I would assum its possible, but I'm trying tyo find out how to get a network share to show up on my mobile devices, pushed through Centrify.

Perhaps there is a way for them to open the CompanyApps app, and there would be a folder that links back to my file server?

Re: Can I add a network share into my Centrfy Company Apps?

$
0
0

,

 

Welcome back.

I would thread carefuly, especially when making assumptions about product behavior.

 

The main capability is working as an IDP.  If you have a company app, typically it is a web or mobile app.

Network shares are a different beast (usually CIFS or NFS filer, and there are identity considerations as well as network prots required) so you won't be able to publish some sort of shortcut like smb://your-server/your-share and expect this to work like your browser will do.

 

There are web interfaces for file shares that expose them via HTTP(s), in that case you may be able to publish that web application, but again, these are not "plug and play" configuraitons like we make others work.

 

We are having a similar issue with organizations wanting to use our app gateway, RDP and SSH secure access as a Terminal Server/Citrix subsitute, and that's not what those solutions are designed for.

 

Just my $0.02.

 

R.P


AD login script not firing, help!

$
0
0

Hey everyone.

 

I'm trying to get this login script to work to change my printer settings from color (default) to black and white...

 

Here's what I've done...

 

I've gone into Group Policy>Computer Configuration>Policies>Centrify Settings>Common Unix Settings>Copy Files

 

I have it set to copy this file to /usr/local/bin

 

This is the script "7545_BW_Login.sh":

 

#!/bin/bash

lpadmin -h 127.0.0.1:631 -p Xerox7545 -o XRColorCorrection=gray

This command does what I want it to do when executed locally.

 

Next I've tried several different aproaches to get this script to fire on login with no success. I'm pretty new to mac management but here's what I've tried...

 

Group Policy>Computer Configuration>Policies>Centrify Settings>Mac OS X Settings>Scripts (Login/Logout) 

I've tried \\mycomp.local\sysvol\mycomp.local\scripts\execute_7545_BW_Login.sh

 

Didn't work.

 

Created an execute script that says this"execute_7545_BW_Login.sh: 

#!/bin/bash

bash /usr/local/bin/7545_BW_Login.sh

Tried putting this script into the computer config login script area.

 

No dice.

 

I've tried putting one / both of these scripts into the user login script with run as root privilidges. 

 

(User Configuration>Centrify Settings>Mac OS X Settings>Scripts (login/logout

 

None of these options have worked. Am I putting the script in the wrong location? There's no evidence that the script is attempting to fire. I can execute either of these script text on my local mac and get them to work, but it's not firing from login via group policy. 

 

I've done gpupdate /force on the AD controller and adgpupdate on my machine and nothing.

 

Any advice? 

 

Re: AD login script not firing, help!

$
0
0

,

 

Welcome to the Centrify community.

 

A general framework to troubleshoot group policy:

 

  1. Make sure the GPO applies to the system in question.  (in AD)
    (e.g. use GPMC resultant set of policies)
  2. Run adgpupdate and then verify with adgpresult. (in Managed client)
  3. If you don't get the GPO, repeat step 1 and also verify communications over SMB
    e.g. adinfo -T [domain controller name]  or adsmb tool.

 

R.P

 

Smart card not reading on centrify express.

$
0
0

I downloaded centrify express, but my smart card does not appear on keychain access.  I do not think the computer is recognizing my smart card.  How do you correct this?

 

Thank you for your time and consideration.

Re: Smart card not reading on centrify express.

$
0
0

Hi ,

 

Welcome to Centrify Community!

 

Normally, when the card reading LED light flashes, it should mean it's loading the content within the card. If 

the card is still not appearing in Keychain Access, then please try these steps:

 

1) Login to the Mac as Local Admin and open Finder

 

2) From the menu bar at the top, click on:
Go > Go to Folder > Enter: /System/Library/Security/tokend/

 

3) Here you should see four tokend files: CAC, CACNG, PIV, and BELPIC
We will try the card against each tokend separately to see if one of them can work properly.

 

4) Create a new folder at: /System/Library/Security/tokend/tmp/

 

5) Move all the tokend files into this new tmp/ folder apart from the one named: PIV.tokend

 

6) Open Keychain Access, and remove and insert your card

 

7) If there is no response in the Keychain, swap out the PIV tokend for another one in the tmp/ folder. We should expect at least one of the tokends to work with your card.

Some background on this method can be found in these articles here:
http://community.centrify.com/t5/The-Centrify-Apple-Guys/About-Centrify-and-PIV-Certificate-Problem/...
http://community.centrify.com/t5/Centrify-Identity-Service/Explaining-U-S-Government-Smart-Cards/ba-...

 

Please let me know the result of the above. Thank you!

 

BR

Ivan

 

Re: Smart card not reading on centrify express.

$
0
0
Thank you, I will give your suggestion a try.

Re: Unable to authenticate to websites using Chrome 63.0.3239.132 on OSX 10.13.2

$
0
0

Just wanted to see if you are still having any issue.

This certificate cannot be used for pkinit

$
0
0

unable to log in to any .mil websites that require CAC cards.  Did everything on this website "https://militarycac.com/". with still no success.  On my CACcard log it siads **    This certificate cannot be used for pkinit.

 

also this is on a MacOS High Sierra


Re: This certificate cannot be used for pkinit

$
0
0

Hi ,

 

Welcome to Centrify!

 

The card may contain multiple certificates which some are not used for authentication and that's why you may get this message.

 

Could you firstly try the following steps in the below link to see if it can help with your situtation?

 

http://community.centrify.com/t5/Centrify-Express/Read-Me-1st-Common-OS-X-Smart-Card-troubleshooting...

 

If the above could not help, could you post us the whole diagnostic output for further investigation? Thanks!

 

Please feel free to contact us if you need any assistance.

 

BR,

Ivan

identify the previous version installed from backup files

$
0
0

Could anyone provide a way to identify the previous version installed from backup files, eg reg entry for Enterprise, Express, etc
We've had a physical DC crash which had this running but have never had to deal with (inherited, appears to have been v3, v4 and currently 5.0.2)

Centrify Corporation Centrify Common Component 3.0.0.100        3.0.0.100       

Centrify Corporation Centrify Deployment Manager 2.1.2.443      2.1.2.443       

Centrify Corporation Centrify DirectControl ADUC Extension 5.0.2.388    5.0.2.388       

Centrify Corporation Centrify DirectControl ADUC Extension 5.0.2.388    5.0.2.388       

Centrify Corporation Centrify DirectControl Console 5.0.2.388   5.0.2.388       

Centrify Corporation Centrify DirectControl Console 5.0.2.388   5.0.2.388       

Centrify Corporation Centrify DirectControl Password Sync 5.0.2.388     5.0.2.388       

Centrify Corporation Centrify DirectControl Password Sync 5.0.2.388     5.0.2.388       

We have backups of the DC however the previous administrator has not kept the install files on the server.
I'm unsure what might happen if we just install the latest express version.

So if possible could also let me know what version of the suite I need to re-install the same version.

Any advice appreciated.

Thanks

Re: identify the previous version installed from backup files

$
0
0

,

 

Welcome to the Centrify forum.

We are happy to point you in the right direction, however, based on the components listed, looks like you are, were or at least tried the commercial version of our software.

 

The most important thing to know is to find out if you are (or were) at some point a commercial customer and how much of a commercial deployment you have (instead of Express).  The last thing you want is to discover that you thought you were using Express, you are not, and then a bunch of critical systems are not accesible because your restore did not take that into consideration.

 

With that said, several potential courses of action here:

  • If you are absolutely sure that you are our software in Express mode AND are using current (5.4.x) Centrify Express clients nothing needs to be done on the AD side (because in this type of deployment there's no "Centrify server components" needed. You can restore your AD environment without issues. 
    Note:  Restorations go different ways sometime, and we don't know your FFL/DFL levels, but should you decide to go from a 2003 to a 2008/2012/2016 AD environment  as part of your recovery, encryption levels will go up, and if you're running 5.0.2 agents, they won't be able to handle the upgrade in encryption levels.  For that you have to be in 5.2 or above.   A consideration for older agents may be the need to restart them or reset the system keytab (which resets the systems's account AD password).
  • If you are not sure if you are using the commercial version, then the very first step is to find out.  Judging from how old the versions listed are (5.0.2.x)  is been EOL for a year, looks like this deployment wasn't kept up to date.  Here's the importance and some comments around each component:
    • Common Component - not very important, as the name describes, it's a set of utilities/capablities common to all Centrify components.   This is not a "server" component, no major worry if it can't be restored.
    • Deployment Manager - this can be reinstalled and re-configured elsewhere.  Some smaller shops use this freeemium utility to distribute our software, but it's been replaced by tools like Chef, Puppet, or scripts leveraging the repo.
    • CDC ADUC extension - as the name says, this is an extension to ADUC.  Since it's just a console, no major worry if it can't be restored.
    • CDC Console - has gone already through 2 name changes; it's now called Access Manager.  Another console, can be installed on any domain-joined system.  No worries here.
    • CDC Password Sync - this is very rarely used nowadays.  Originally a "mee too" capability, but in reality not widely adopted due to it's need to be deployed in DCs.    This is the only reason why you need to find out if you are using the commercial version.   You would know if you have UNIX accounts (like root) that are mapped to a specific AD user and when the password is changed in AD, it's synced to UNIX systems.

Tips to find out if you're using the commercial version vs. express version:

  • Not all users and groups are visible in your UNIX, Linux or Mac systems.  (adquery user).
  • You have access to clients for OSs that are not offered in the Express program (like HP-UX).
  • You have a support account with access to the Download Center and your support contract is current.
  • Your systems are joined to a named "zone"  rather than Auto Zone  (adinfo --zone).
  • You needed to use the consoles to specifically grant access to users to UNIX/Linux systems.
  • There is a deployment playbook left behind by Centrify professional servicdes.

 

What you need to download?

If Express:

  • You may or may not have deployed Deployment Manager.  This is not a critical component for functionality (it's used for deployments).   You can download from the Express download page.
  • Clients - should you need updated clients. You can download from the Express download page.

Expess page:  https://www.centrify.com/express/linux/download/   (you'll have to fill the form).

 

If commercial software:

(Note that the new product packaging includes our IDaaS platform and Vault).

Both links above require Customer Support Portal access.

 

What could have happened?

  • Your organization could have evaluated the commercial version and decided not to go with it but chose to roll out Express.  In that case the consoles are there because of this.  (I think this is the best outcome for quick recovery).
  • Your organization at some point was using the commercial version, and simply let your support lapse in favor of keeping the software running without the additional cost.  In that case, you are likely to some assistance to rebuild, plus you'll need to download current supported software.  In that case, please discuss with support to get options.  They'll have to study your deployment to give you the best course of action.  This will definitely slow down your recovery.
  • Your organization chose to keep old "Express" agents prior to 5.2 (when due to abuse, we limited some features of the freemium version), because you wanted to retain the old functionality.  In that case, the problem with that strategy has to do with due diligence.  Any decent security practicioner knows that one of the most basic principles is to keep software up to date or at least patched.  A lot has happened since 5.0.2 (released in Feb 2012).  In that case, ideally all the agents have to be upgraded (especially if wanting to take advantage of newer Centrify and AD capabilities).

Finally, since this is likely to be read by people in the future, in the community there are resources that are useful:

 R.P

VNC with centrify (pam?)

$
0
0

Good Afternoon,


I am working for a client who uses Centrify software on their RHEL7 servers. I have been reaching out on all channels to implement a change that they requested. Basically, Centrify accounts work fine with normal SSH logins, but using the rhel supported tigervnc-server, a separate password is requested. Are you aware if there is a documented solution using Centrify to log in with the same credentials both to ssh and VNC?


Thank you,

-Paul

Re: VNC with centrify (pam?)

$
0
0

,

 

Welcome to the Centrify forums.

 

I would make sure the VNC server is configured to use the proper PAM modules. 

Looking at http://tigervnc.org/doc/Xvnc.html it seems there's a parameter:

 

−pam_service name, −PAMService name

 

As a courtesy, here's an article from the KB (refers to a different VNC server, but looks promising)

 

KB-0495: Configure Enterprise VNC to authenticate with Centrify DirectControl

Centrify DirectControl ,  

12 April,16 at 10:57 AM

 
Question:

How to implement VNC for Unix?

Answer:

Enterprise VNC for Unix from RealVNC is implemented using the Unix authentication option; it can use PAM for Authentication.

In Enterprise VNC, the option, PamApplicationName, specifies the PAM application policy to use. By default, its value is vncserver.

To enable Enterprise VNC to do authentication with Centrify DC, it can be done by one of the following options:
  1. Set PamApplicationName to "other" by setting the option in VNC config file in /etc/vnc/config, or by applying the command option --PamApplicationName=other
     
  2. Edit vncserver entries in the pam config file to contain Centrify pam modules.

    E.g. Edit lines in pam.conf to contain the Centrify pam modules for system such as HP-UX, and Solaris. Or copy /etc/pam.d/system-auth as /etc/pam.d/vncserver for systems such as Redhat Linux

 

We encourage you to share your results with the community to benefit future readers.

 

R.P

Viewing all 1833 articles
Browse latest View live


Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>